Tag: Windows 11

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
News

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

On a fully updated Windows 11 computer, Windows Plug and Play can be exploited to retrieve signed vendor software for an emulated USB device and run privileged installation components that researchers tied to SYSTEM access. When compatible Plug and Play or low-level USB redirection is enabled, the same PnP path can be initiated via Remote Desktop without the need for actual hardware; Microsoft claims that redirection is not permitted by default. In "Plug And Pwn: Weaponizing Windows PnP Auto-Install," a study prepared for DEF CON 34, security experts Alejandro Hernando and Borja Martinez detailed the method. They developed tools to simulate any USB device and claimed that an unauthorized user could convert the PnP installation path into SYSTEM code execution under certain circums...
Windows 11 now supports 3rd-party apps for native passkey management
News

Windows 11 now supports 3rd-party apps for native passkey management

Microsoft declared that Windows 11 now offers easier passwordless authentication due to its native compatibility with third-party passkey managers, starting with support for 1Password and Bitwarden. This became achievable due to collaboration between the Windows security team and third-party managers, aimed at enhancing passwordless authentication through the creation of a passkey API for Windows 11. A new feature was added with the November 2025 security update for Windows 11, which was released yesterday. Passkeys, which adhere to the FIDO2/WebAuthn standards, use private-public key cryptography for local challenge signing and server-side verification instead of passwords, providing a secure authentication mechanism. Upon users’ registration on a passkey-enabled application or ...
Windows 11 and Red Hat Linux hacked on first day of Pwn2Own
News

Windows 11 and Red Hat Linux hacked on first day of Pwn2Own

Security researchers who successfully demonstrated zero-day attacks for Windows 11, Red Hat Linux, and Oracle VirtualBox were given $260,000 on the first day of Pwn2Own Berlin 2025. After Pumpkin from the DEVCORE Research Team took use of an integer overflow vulnerability to make $20,000, Red Hat Enterprise Linux for Workstations became the first to be classified as a local privilege escalation. By combining a use-after-free with an information leak, Hyunwoo Kim and Wongi Lee were also able to gain root access on a Red Hat Linux device; however, one of the exploited vulnerabilities was an N-day, which resulted in a bug collision. Then, Chen Le Qi of STARLabs SG received $30,000 for a chain of exploits that escalated access to SYSTEM on a Windows 11 system by combining an integer ...
Microsoft Introduces Linux-Like ‘sudo’ Command to Windows 11
News

Microsoft Introduces Linux-Like ‘sudo’ Command to Windows 11

Microsoft said that to facilitate the execution of commands with administrator capabilities, Sudo will be included in an early preview version of Windows 11. Microsoft Product Manager Jordi Adoumie stated, "Sudo for Windows is a new way for users to run elevated commands directly from an unelevated console session." "It is an ergonomic and familiar solution for users who want to elevate a command without having to first open a new elevated console." For Unix-like computer operating systems, the software sudo, short for superuser do, enables users to execute programs with the security capabilities read more Microsoft Introduces Linux Like sudo Command to Windows 11. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough cov...
New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections
News

New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections

Researchers studying security have discovered a novel form of dynamic link library (DLL) search order hijacking that threat actors might employ to get around security measures and execute malicious code on Microsoft Windows 10 and Windows 11 platforms. The cybersecurity company Security Joes stated in a new study that was privately shared with The Hacker News that the strategy "leverages executables commonly found in the trusted WinSxS folder and exploits them via the classic DLL search order hijacking technique." By doing this, adversaries can, as has been seen in the past, insert potentially vulnerable binaries into the attack chain and do away with the requirement for elevated privileges read more New Variant of DLL Search Order Hijacking Bypasses Windows 10 and 11 Protections. ...
Microsoft is Rolling out Support for Passkeys in Windows 11
News

Microsoft is Rolling out Support for Passkeys in Windows 11

As part of a significant update to the desktop operating system, Windows 11 now formally introduces support for passkeys. Through the use of their device PIN or biometric data, users are able to log into websites and applications without having to enter their username and password. Passkeys was initially introduced in May 2022 as a password replacement that is both secure and resistant to phishing attacks based on FIDO standards. Since then, Apple, Google, and a number of other services have all adopted it. Passkey management was already a function in the tech giant's Windows Insider program as of June 2023 read more Microsoft is Rolling out Support for Passkeys in Windows 11. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our compre...